Consultant, FedRAMP Assessment

Coalfire

United States

On-site

USD 71,000 - 122,689

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible work model
Paid parental leave
Certification reimbursement
Digital mental health support

Job summary

Coalfire is seeking a Security Consultant to join their team in the United States. This role involves assessing clients' security compliance with regulatory standards, conducting audits, and managing project timelines. Candidates should have 2-3 years of IT experience, familiarity with NIST publications, strong communication skills, and a Bachelor's degree in IT or business. The position offers a salary ranging from $71,000 to $122,689 annually, flexible working options, and competitive benefits.

Qualifications

  • Minimum 2-3 years of experience in IT.
  • Experience with NIST cybersecurity frameworks.
  • Ability to assess security vulnerabilities.

Responsibilities

  • Work collaboratively as a federal compliance specialist.
  • Lead interviews with clients to assess compliance.
  • Prepare and review assessment reports.

Skills

Strong familiarity with NIST Special Publications 800-37, 800-53
Technical understanding of NIST 800-53 control families
Strong written and verbal communication
Ability to manage time effectively
Consulting skills

Education

Bachelor’s degree in IT or business

Tools

Nessus
Firewalls
Microsoft

Job description

About Coalfire

Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.

But that’s not who we are – that’s just what we do.

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

Position Summary

The Security Consultant will work as part of a team assessing the security and compliance of client firms against regulatory and industry requirements and standards, and against security best practice frameworks. This role will have a strong understanding of framework requirements, perform audit/assessments, and develop reports for clients. They will work closely with Project Managers, Senior Managers, Directors and other Delivery team members to effectively manage project timelines and deliverables.

What You’ll Do
  • Work collaboratively with a team of assessors as a federal compliance specialist (e.g. FedRAMP, NIST 800-171, FISMA, etc.) and assist with the planning of assessment for clients
  • Draft audit observations that sufficiently address both the required objectives of the regulatory body and the complexity of the client environment
  • Autonomously leads interview and inquiry walkthroughs with clients to determine the conformity of environments against stated requirements
  • Assess security vulnerabilities against the appropriate security frameworks
  • First-level reviewer of drafted audit planning and reporting materials
  • Pursue and corroborates conclusions derived from inquiry procedures with client while ensuring diligent interview notes are captured
  • Offline and remote evidence inspection of client provided documentation; appropriately mark artifacts requiring follow-up or additional clarification
  • Assess client provided documentation for compliance with a variety of standards
  • Prepare and review assessment reports
  • Educate and interpret compliance activities for clients
  • Manage priorities and tasks to achieve delivery utilization targets
  • Ensure quality products and services are delivered on time per Coalfire quality standards
  • Continuous professional development; maintain industry specific certifications, depth of knowledge, credentials, and designations
  • Collaborate with project managers, quality management and/or other delivery team members to drive customer satisfaction and meet project deliverables
  • Establish and maintain positive collaborative relationships with clients and stakeholders
  • Identify upsell and cross sell opportunities; escalates to appropriate leadership
  • Execute, examine, interview and test procedures in accordance with the appropriate control
  • Ensure cyber security policies are adhered to and that required controls are implemented
  • Review and assess respective information system security plans to ensure control requirements are met
  • Understand how to apply quality standards and adheres to a minimum benchmark for quality assurance throughout the documentation of each work product or deliverable
  • Provide advice to customers on issues affecting the scope of work in a manner that provides additional value
  • Develop documentation and author recommendations associate with your findings on how to improve the customer’s security posture in accordance with appropriate controls
  • Travel 20%
What You’ll Bring
  • Minimum 2-3 years of experience in the IT industry, with strong familiarity with the applicable NIST Special Publications 800-37 Revision 2, 800-53 Revision 5, and 800-53A Revision 5
  • Technical and detailed understanding of NIST 800-53 Rev 5 AT, CA, CM, CP, IR, MA, MP, PE, PL, PS, RA, SA, SI control families
  • Ability to lead testing sessions for assigned controls
  • Ability to independently research a technical topic and develop logical testing approaches to validate 800-53 control implementations
  • Ability to assist team members with proper artifact collection and detail to client’s examples of artifacts that will satisfy assessment requirements
  • Read and interpret all control families
  • Read and interpret firewall rulesets and network/boundary/data flow diagrams
  • Strong written and verbal communication skills including the ability to explain technical matters to a non-technical audience
  • Strong personal initiative to appropriately manage time and meet deadlines
  • Strong Consulting skills; ability to advise and challenge the status quo while building strong relationships
  • Ability to build high-trust relationship and credibility quickly
  • High attention to detail
  • Ability to facilitate meetings to small or large groups
  • Diplomatic and broad minded
  • Strong technical researcher
  • Bachelor’s degree (four-year college or university) in IT or business, or equivalent combination of education and work experience
Certifications
  • Cisco Certified Network Associate Security (CCNA Security)
  • Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops)
  • Cybersecurity Analyst (CySA+)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Systems and Network Auditor (GSNA)
  • GIAC Certified Intrusion Analyst (GCIA)
  • Certified Information Systems Auditor (CISA)
  • Certified Information System Security Professional or Associate (CISSP or Associate)
  • Certified Secure Software Lifecycle Professional (CSSLP)
  • Certified Information Systems Security Officer (CISSO)
  • CyberSec First Responder (CFR)
  • CompTIA Advanced Security Practitioner Continuing Education (CASP+) Continuing Education (CE)
  • CompTIA Cloud+ (Cloud+)
  • Global Industrial Cyber Security Professional (GICSP)
  • Securing Cisco Networks with Threat Detection Analysis (SCYBER)
  • BCR Cyber Technical Proficiency Testing Activity
Bonus Points
  • Expertise in security frameworks and regulatory requirements (such as SOC 2, ISO, NIST, COBIT, HIPAA/HITECH, HITRUST or PCI).
  • Experience working with technologies hosted via cloud computing environments (e.g., Amazon Web Services, Microsoft Azure, Google Cloud Platform)
  • Experience reviewing Nessus output a plus, along with basic knowledge of networking components and various operating systems in a cloud environment, including UNIX and Microsoft.
  • Expertise in other Security Frameworks (ISO, NIST, COBIT, HIPAA/HITECH, etc.) and regulatory requirements.
  • A2LA R311 certification:
    • CompTIA Advanced Security Practitioner (CASP+) Continuing Education (CE)
    • GIAC Certified Enterprise Defender (GCED)
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Security Leadership (GSLC)
    • Certified Information Systems Auditor (CISA)
    • Certified Information Security Manager (CISM)
    • Certified Cloud Security Professional (CCSP)
    • CISSP-Information Systems Security Architecture Professional (CISSP-ISSAP)
    • CISSP-Information Systems Security Engineering Professional (CISSP-ISSEP)
    • CISSP-Information Systems Security Management Professional (CISSP-ISSMP)
    • CyberSec First Responder (CFR)
    • Certified Chief Information Security Officer (CCISO)
    • BCR Cyber Technical Proficiency Testing Activity
Salary

$71,000 - $122,689 a year

The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs.

Why You’ll Want to Join Us

At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.

Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.

At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at HumanResourcesMB@coalfire.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate, FedRAMP Assessment
Associate, FedRAMP Assessment

Coalfire • United States

Hybrid
USD 70,000 - 90,000
Paid parental leave
Flexible time off
Certification and training reimbursement
+2
Senior Consultant, FedRAMP Assessment
Senior Consultant, FedRAMP Assessment

Coalfire • United States

On-site
USD 86,000 - 148,000
Paid parental leave
Flexible time off
Certification and training reimbursement
Associate, Compliance Security Penetration Tester
Associate, Compliance Security Penetration Tester

Coalfire- • Chicago (IL)

Hybrid
USD 64,000 - 117,000
Flexible work model
Parental leave
Certification and training reimbursem
Principal Cloud Engineer
Principal Cloud Engineer

Coalfire- • United States

Remote
USD 109,000 - 182,000
Flexible work model
Competitive benefits
Associate, Compliance Security Penetration Tester
Associate, Compliance Security Penetration Tester

Coalfire • United States

Hybrid
USD 120,000 - 180,000
Associate, Compliance Security Penetration Tester
Associate, Compliance Security Penetration Tester

Socket.dev • United States

Hybrid
USD 120,000 - 180,000
Senior Consultant, Network Security
Senior Consultant, Network Security

Coalfire • United States

Hybrid
USD 140,000 - 180,000
paid parental leave
flexible time off
certification and training reimburse"
+2
Senior Technical Project Manager (Cloud and Compliance)
Senior Technical Project Manager (Cloud and Compliance)

Coalfire • United States

Hybrid
USD 110,000 - 150,000
Paid parental leave
Flexible time off
Certification reimbursement
+2
Security Engineer (Splunk)
Security Engineer (Splunk)

Coalfire • United States

Hybrid
USD 78,000 - 135,000
Paid parental leave
Flexible time off
Certification and training reimbursement
+2
Engagement Architect - Cloud Architecture (FedRAMP)
Engagement Architect - Cloud Architecture (FedRAMP)

Coalfire- • Chicago (IL)

Hybrid
USD 89,000 - 149,000